Vulnerability CVE-2021-43951


Published: 2022-01-10

Description:
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Atlassian -> Data center 
Atlassian -> Jira service management 

 References:
https://jira.atlassian.com/browse/JSDSERVER-10984

Copyright 2024, cxsecurity.com

 

Back to Top